Indicator Server Configurations
Review indicator server configurations in Cortex XSOAR 6.13.
create.indicators.limit.by.time.range
Whether to limit the period of time to fetch indicators.
true
create.indicators.limit.by.time.range.hour
The period of time (hours) within which to limit indicators that can be fetched.
24
create.indicators.limit.by.time.range.max.allowed
The maximum number of indicators that can be fetched within the time period defined in the following server configuration: create.indicators.limit.by.time.range.hours
1000
create.indicators.limit.by.total.amount
Whether to limit the total number of indicators that can be fetched.
false
create.indicators.limit.by.total.amount.max.allowed
The maximum number of total indicators that can be fetched by default.
5000000
create.indicators.limit.by.total.amount.warning.percentage
The percentage of indicators fetched, calculated from create.indicators.limit.by.total.amount.max.allowed, after which warning messages are sent to defined users.
75
create.related.indicators.entry
Whether to disable War Room notifications for related indicators. For more information, see War Room Overview.
true
enrichment.reputationScript.reliability
The reliability of the score from a reputation script. For more information, see Indicator Type Profile.
A++
indicator.feed.html.field.truncate.maxChars
To change the maximum size in KB to display the HTML field. If you increase the limit substantially, it may slow performance. For more information, see Configure the HTML Field.
50
indicator.html.style.attributes
If HTML is missing some styles, add the missing styles. For more information, see Configure the HTML Field.
N/a
indicator.investigationids.maxlen
The maximum number of investigation IDs saved per indicator prevents the number of related incidents of an indicator from increasing significantly, causing memory issues/outage on the server. When defined, the number of associated investigation IDs will be limited to "maxlen". If a new ID is associated with the indicator, the oldest ID will be removed. Use 0 for "unlimited" (the default and current behavior).
0
indicator.timeline.auto.extract.enabled
Enables the indicator timeline in the indicator extraction flow. For more information, see Configure the Indicator Timeline.
true
indicator.timeline.enabled
Enables the indicator timeline in all flows. For more information, see Configure the Indicator Timeline.
true
indicator.timeline.enabled.type.<indicatorType>
Enables the indicator timeline for a specific indicator type. For more information, see Configure the Indicator Timeline.
true
indicator.timeline.max.size
The maximum number of indicator comments (timeline and regular). For more information, see Configure the Indicator Timeline.
100
indicator.timeline.worker.enabled
Enables you to add timeline comments through content integrations. For more information, see Configure the Indicator Timeline.
true
message.ignore.fetchIndicator.warning
Indicates whether to send warning messages to defined users.
This is an alternative to the previous set of configurations, which sets the limit according to the total number and the defined time period.
false
reputation.calc.algorithm.tasks
Applies to the result of the task. You can change the value when editing a task, which overrides the system configuration for this task. For more information, see Indicator Extraction Modes.
none
reputation.calc.algorithm
Sets the global indicator extraction mode, which affects all extraction processes, including incident creation, playbooks, and automation. It is also used to troubleshoot performance issues, such as playbooks taking a long time to start.
Available modes:
1- None
2 - Inline
3 - Out of band
For more information, see Indicator Extraction Modes.
2 (inline)
reputation.calc.algorithm.fields.change
Sets the indicator extraction mode for incident field change. You can change the value when editing an incident type, which overrides this system configuration for this incident type. For more information, see Indicator Extraction Modes.
3 (out of band)
reputation.calc.algorithm.manual
Applies to commands triggered from the CLI. You can change the value when using the auto-extract parameter, which overrides the system configuration for this command.
For more information, see Indicator Extraction Modes.
3 (Out of band)
reputation.notification.max.count
The maximum number of notifications of reputation indicators in a batch update.
100
ThreatIntelReport.default.readonly.roles
Grants read-only access to Threat Intel reports. Value: List of comma-separated users.
N/a
ThreatIntelReport.default.roles
Grands read and write access to Threat Intel Reports. Value: List of comma-separated users.
N/a
UI.html.use.theme.css
Whether to use Cortex XSOAR theme styles. For more information, see Configure the HTML Field.
true
UI.investigation.page
Customizes the default landing page within the incident view. Values:
/Details//WarRoom//WorkPlan//EvidenceBoard/
/Details/
UI.summary.page.hide.empty.fields
Whether to hide empty fields in the incident summary tab. For more information, see Indicator Layouts.
true
Last updated
Was this helpful?
